Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16.05.2018 01
Ran by BEBOP (administrator) on MAX (16-05-2018 17:55:17)
Running from C:\Users\BEBOP\Desktop
Loaded Profiles: BEBOP (Available Profiles: BEBOP & Administrator)
Platform: Windows 10 Home Version 1709 16299.371 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.2.4.1\WsAppService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\System32\Locator.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(f.lux Software LLC) C:\Users\BEBOP\AppData\Local\FluxSoftware\Flux\flux.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\Overwolf.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareTactXMacroController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\0.114.1.39\OverwolfBrowser.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\0.114.1.39\OverwolfBrowser.exe
(Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.114.1.39\OverwolfHelper.exe
(Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.114.1.39\OverwolfHelper64.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Dell Inc.) C:\Program Files (x86)\Alienware Update\DellUpService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(Dell Inc.) C:\Program Files (x86)\Alienware Update\DellUpTray.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Azureus Software, Inc) C:\Program Files (x86)\Vuze\Azureus.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(PC-Doctor, Inc.) C:\Program Files\Alienware\SupportAssist\imstrayicon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [14056 2014-10-30] (Alienware)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-04-28] (Adobe Systems Incorporated)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-08-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-04] (Realtek Semiconductor)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [315880 2018-01-05] (Adobe Systems, Incorporated)
HKLM-x32\...\Run: [NoteBurner] => C:\Program Files (x86)\NoteBurner\VTBurnerGUI.exe [4345856 2007-12-19] (NoteBurner.COM)
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [366904 2015-10-08] (Power Software Ltd)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3428963390-2178166571-3703012988-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3199776 2018-04-02] (Valve Corporation)
HKU\S-1-5-21-3428963390-2178166571-3703012988-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18334528 2018-04-12] (Piriform Ltd)
HKU\S-1-5-21-3428963390-2178166571-3703012988-1001\...\Run: [Discord] => C:\Users\BEBOP\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-04-30] (Discord Inc.)
HKU\S-1-5-21-3428963390-2178166571-3703012988-1001\...\Run: [f.lux] => C:\Users\BEBOP\AppData\Local\FluxSoftware\Flux\flux.exe [1678840 2017-10-10] (f.lux Software LLC)
HKU\S-1-5-21-3428963390-2178166571-3703012988-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [5345672 2017-12-21] (Nota Inc.)
HKU\S-1-5-21-3428963390-2178166571-3703012988-1001\...\Run: [Gaijin.Net Agent] => C:\Users\BEBOP\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [2116168 2018-01-30] (Gaijin Entertainment)
HKU\S-1-5-21-3428963390-2178166571-3703012988-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1208648 2018-05-15] ()
HKU\S-1-5-21-3428963390-2178166571-3703012988-1001\...\MountPoints2: F - "F:\Setup.exe"
Startup: C:\Users\BEBOP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2016-03-18] ()
Startup: C:\Users\BEBOP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\landscape.lnk [2018-04-19]
ShortcutTarget: landscape.lnk -> C:\Program Files (x86)\Rapport\Adman.exe (No File)
Startup: C:\Users\BEBOP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\landscapelandscape.lnk [2018-04-19]
ShortcutTarget: landscapelandscape.lnk -> C:\Program Files (x86)\inert\fy.exe (No File)
Startup: C:\Users\BEBOP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2015-12-15]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (No File)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{717570d3-2bd1-4a90-8857-320e4151b57e}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{c5e082f5-da24-4eea-a6ac-61e66b5e6177}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Internet Explorer:
==================
HKU\S-1-5-21-3428963390-2178166571-3703012988-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://
www.msn.com/?ocid=iehp
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-04-17] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-17] (Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
FireFox:
========
FF DefaultProfile: ihax6t3x.default
FF ProfilePath: C:\Users\BEBOP\AppData\Roaming\Mozilla\Firefox\Profiles\ihax6t3x.default [2018-05-16]
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: @EDVR/WebClient -> C:\windows\system32\WebClient\npwebclient.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-18] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-18] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-17] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-05-07] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-05-07] (NVIDIA Corporation)
FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\BEBOP\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-05-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-05-13] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: BYOND -> C:\Program Files (x86)\BYOND\bin\npbyond.dll [No File]
FF Plugin HKU\S-1-5-21-3428963390-2178166571-3703012988-1001: jpl.nasa.gov/NASAEyes -> C:\Users\BEBOP\AppData\Roaming\JPL-NASA-Caltech\NASA's Eyes\npNASAEyes.dll [2017-08-11] (Jet Propulsion Laboratory)
Chrome:
=======
CHR HomePage: Default -> hxxp://search.conduit.com/?SearchSource=10&ctid=CT3059010
CHR StartupUrls: Default -> "chrome://extensions/"
CHR Profile: C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default [2018-05-16]
CHR Extension: (Slides) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-13]
CHR Extension: (Docs) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-13]
CHR Extension: (Google Drive) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-05-13]
CHR Extension: (YouTube) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-13]
CHR Extension: (Firebug Lite for Google Chrome™) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmagokdooijbeehmkpknfglimnifench [2018-05-13]
CHR Extension: (HP Print for Chrome) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjanmonomjogheabiocdamfpknlpdehm [2018-05-13]
CHR Extension: (uBlock Origin) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2018-05-13]
CHR Extension: (Sheets) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-13]
CHR Extension: (HTTPS Everywhere) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2018-05-13]
CHR Extension: (Google Docs Offline) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-13]
CHR Extension: (Save to Google Drive) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbmikajjgmnabiglmofipeabaddhgne [2018-05-13]
CHR Extension: (View Image) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpcmhcelnjdmblfmjabdeclccemkghjk [2018-05-16]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2018-05-15]
CHR Extension: (Wicked Good Unarchiver) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\mljpablpddhocfbnokacjggdbmafjnon [2018-05-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-13]
CHR Extension: (Personal Blocklist (by Google)) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nolijncfnkgaikbjbdaogikpmpbdcdef [2018-05-13]
CHR Extension: (Checker Plus for Gmail™) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2018-05-13]
CHR Extension: (Gmail) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-05-13]
CHR Extension: (Chrome Media Router) - C:\Users\BEBOP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-13]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [683696 2015-11-16] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6076936 2018-05-08] ()
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058392 2017-12-12] (Microsoft Corporation)
R2 DellUpdate; C:\Program Files (x86)\Alienware Update\DellUpService.exe [237016 2018-03-27] (Dell Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S3 ioloEnergyBooster; C:\Program Files\Alienware\Command Center\ioloEnergyBooster.exe [6145872 2012-11-01] (iolo technologies, LLC)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-18] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-03] (Malwarebytes)
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3916368 2016-01-09] (INCA Internet Co., Ltd.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-23] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-23] (NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1966408 2018-05-15] (Overwolf LTD)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [312056 2015-08-04] (Realtek Semiconductor)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-16] (DEVGURU Co., LTD.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [263264 2017-02-24] (Synaptics Incorporated)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.2.4.1\WsAppService.exe [417792 2016-07-12] (Wondershare) [File not signed]
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\Dr.Fone for Android\DriverInstall.exe [103736 2015-09-22] (Wondershare)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [19440 2015-11-10] (OSR Open Systems Resources, Inc.)
S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo64.sys [31376 2015-03-10] ()
R0 EMSC; C:\WINDOWS\System32\drivers\EMSC.SYS [17720 2012-07-10] ()
R0 EMSC; C:\Windows\SysWOW64\drivers\EMSC.SYS [15160 2012-07-10] ()
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [152184 2018-05-15] (Malwarebytes)
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [27552 2016-01-03] (REALiX(tm))
R3 KillerEth; C:\WINDOWS\System32\drivers\e2xw10x64.sys [145920 2017-09-29] (Qualcomm Atheros, Inc.)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [190696 2018-05-15] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [112864 2018-05-16] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [44768 2018-05-16] (Malwarebytes)
R1 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [253664 2018-05-10] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [103648 2018-05-16] (Malwarebytes)
S3 mcaudrv_simple; C:\WINDOWS\system32\drivers\mcaudrv_x64.sys [35960 2014-12-28] (Visicom Media Inc.)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-18] (Intel Corporation)
S3 ntcdrdrv; C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys [25680 2011-01-06] (NoteBurn Software)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvdmi.inf_amd64_5a184893dfb38fc1\nvlddmkm.sys [17168744 2018-05-08] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [31168 2018-03-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [59240 2018-03-23] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [58816 2018-05-07] (NVIDIA Corporation)
S3 RAZERSEIREN; C:\WINDOWS\system32\DRIVERS\SEIREN.sys [3806920 2015-11-29] (Razer Inc.)
U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [865216 2018-05-14] (Realsil Semiconductor Corporation)
U5 RTSUER; C:\Windows\System32\Drivers\RTSUER.sys [424384 2018-05-14] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [72288 2017-02-24] (Synaptics Incorporated)
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [84432 2017-03-27] (The OpenVPN Project)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2015-06-10] (Apple, Inc.) [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2018-04-25] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [313888 2018-04-25] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61472 2018-04-25] (Microsoft Corporation)
R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
S4 pbicvmra; System32\drivers\exhzbkgv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-05-16 02:12 - 2018-05-16 16:11 - 000000000 ____D C:\Users\BEBOP\AppData\Local\NFS Underground 2
2018-05-16 02:12 - 2018-05-16 02:12 - 000000804 _____ C:\Users\BEBOP\Desktop\Need for Speed Underground 2.lnk
2018-05-16 02:12 - 2018-05-16 02:12 - 000000804 _____ C:\Users\BEBOP\AppData\Roaming\Microsoft\Windows\Start Menu\Need for Speed Underground 2.lnk
2018-05-16 02:12 - 2018-05-16 02:12 - 000000000 ____D C:\Users\BEBOP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2018-05-16 02:04 - 2018-05-16 02:04 - 000000000 ____D C:\Users\BEBOP\Documents\Vuze Downloads
2018-05-15 22:39 - 2018-05-15 22:40 - 000000000 ____D C:\WINDOWS\HP
2018-05-15 22:39 - 2018-05-15 22:39 - 000000000 ____D C:\swsetup
2018-05-15 22:27 - 2018-05-16 15:03 - 000103648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2018-05-15 22:25 - 2018-05-15 22:25 - 000000000 ____D C:\Users\BEBOP\AppData\Local\vsohigz
2018-05-15 22:00 - 2018-05-15 22:14 - 000000000 ____D C:\Users\BEBOP\Desktop\New folder (2)
2018-05-15 19:37 - 2018-05-15 19:37 - 000000000 ____D C:\Users\BEBOP\AppData\Local\lmmweta
2018-05-15 19:01 - 2018-05-15 19:01 - 000000000 ____D C:\Users\BEBOP\AppData\Local\scslkur
2018-05-15 15:18 - 2018-05-04 05:37 - 000278448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Notifier.exe
2018-05-15 15:14 - 2018-05-15 15:14 - 000000000 ____D C:\Users\BEBOP\AppData\Local\exmwtlz
2018-05-15 06:04 - 2018-05-15 06:04 - 000003900 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2018-05-15 05:21 - 2018-05-16 15:08 - 000003614 _____ C:\WINDOWS\System32\Tasks\Pcd.DriverScan.VKP80
2018-05-15 05:21 - 2018-05-15 05:21 - 000000000 ____D C:\ProgramData\PC-Doctor, Inc
2018-05-15 05:05 - 2018-05-15 05:05 - 000004128 _____ C:\WINDOWS\System32\Tasks\PCDoctorBackgroundMonitorTask
2018-05-15 05:05 - 2018-05-15 05:05 - 000003580 _____ C:\WINDOWS\System32\Tasks\PCDEventLauncherTask
2018-05-15 05:05 - 2018-05-15 05:05 - 000003404 _____ C:\WINDOWS\System32\Tasks\PCDDataUploadTask
2018-05-15 05:05 - 2018-05-15 05:05 - 000003286 _____ C:\WINDOWS\System32\Tasks\SystemToolsDailyTest
2018-05-15 05:05 - 2018-05-15 05:05 - 000000000 ____D C:\ProgramData\PC-Doctor for Windows
2018-05-15 05:04 - 2018-05-15 05:04 - 002219736 _____ (Dell Inc) C:\Users\BEBOP\Downloads\aulauncher.exe
2018-05-15 04:32 - 2018-05-15 22:24 - 000092227 _____ C:\WINDOWS\system32\battery-report.html
2018-05-15 04:14 - 2018-05-15 04:14 - 011314776 _____ (Igor Pavlov) C:\Users\BEBOP\Downloads\VAS10A13.exe
2018-05-15 04:13 - 2018-05-15 04:13 - 000000000 ____D C:\Users\BEBOP\AppData\LocalLow\Intel
2018-05-15 04:03 - 2018-05-15 06:03 - 000000000 ____D C:\Program Files\Dell
2018-05-15 04:03 - 2018-05-15 04:03 - 000398288 _____ (Oleg N. Scherbakov) C:\Users\BEBOP\Downloads\SupportAssistLauncher.exe
2018-05-15 04:03 - 2018-05-15 04:03 - 000000000 ____D C:\ProgramData\SupportAssist
2018-05-15 04:03 - 2018-05-15 04:03 - 000000000 ____D C:\ProgramData\Dell Inc
2018-05-15 03:42 - 2018-05-15 03:42 - 000000000 ____D C:\Users\BEBOP\AppData\Local\scemkor
2018-05-15 03:41 - 2018-05-16 01:48 - 000112864 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2018-05-15 03:41 - 2018-05-16 01:48 - 000044768 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2018-05-15 03:41 - 2018-05-15 22:29 - 000190696 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2018-05-15 03:37 - 2018-05-15 03:37 - 000000000 ____D C:\Users\BEBOP\AppData\Local\nvhaxou
2018-05-15 02:55 - 2018-05-15 02:55 - 000000000 ____D C:\Users\BEBOP\AppData\Local\sidczat
2018-05-15 02:40 - 2018-05-15 02:40 - 000000000 ____D C:\Users\BEBOP\AppData\Local\mbsdoap
2018-05-15 02:34 - 2018-05-15 02:34 - 000000000 ____D C:\Users\BEBOP\AppData\Local\secudbx
2018-05-15 02:26 - 2018-05-15 02:26 - 000000000 ____D C:\Users\BEBOP\AppData\Local\vdswgma
2018-05-15 02:18 - 2018-05-15 02:18 - 000000000 ____D C:\Users\BEBOP\AppData\Local\upazrdt
2018-05-14 16:13 - 2018-05-14 16:13 - 001828618 _____ C:\Users\BEBOP\Downloads\mlb tickets 1.pdf
2018-05-14 16:13 - 2018-05-14 16:13 - 001565513 _____ C:\Users\BEBOP\Downloads\mlb tickets 2.pdf
2018-05-14 06:38 - 2018-05-14 06:38 - 000000000 ____D C:\Users\BEBOP\AppData\Local\exmtgks
2018-05-14 02:20 - 2018-05-14 02:20 - 000000000 ____D C:\Users\BEBOP\AppData\Local\cgrszdp
2018-05-14 02:17 - 2018-05-14 02:18 - 000000021 _____ C:\Users\BEBOP\Desktop\info tax.txt
2018-05-14 02:17 - 2018-05-14 02:17 - 000000000 ____D C:\Users\BEBOP\Desktop\New folder
2018-05-14 02:14 - 2018-05-14 02:14 - 018151984 _____ C:\Users\BEBOP\Downloads\0007-RtsXStor_10.0.370.188.zip
2018-05-14 02:14 - 2018-05-14 02:14 - 009891328 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RsCRIcon.dll
2018-05-14 02:14 - 2018-05-14 02:14 - 000865216 _____ (Realsil Semiconductor Corporation) C:\WINDOWS\system32\Drivers\RtsPer.sys
2018-05-14 02:14 - 2018-05-14 02:14 - 000424384 _____ (Realsil Semiconductor Corporation) C:\WINDOWS\system32\Drivers\RtsUer.sys
2018-05-14 02:14 - 2018-05-14 02:14 - 000338880 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RtsBaStor.sys
2018-05-14 02:14 - 2018-05-14 02:14 - 000329664 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RtsP2Stor.sys
2018-05-14 02:14 - 2018-05-14 02:14 - 000000000 ____D C:\Program Files (x86)\Realtek
2018-05-13 23:47 - 2018-05-13 23:47 - 000013649 _____ C:\Users\BEBOP\Downloads\2017-taxdocuments-x9121-.pdf
2018-05-13 23:13 - 2018-05-13 23:13 - 000379392 _____ C:\Users\BEBOP\Downloads\subinacl.msi
2018-05-13 07:33 - 2018-05-13 07:33 - 000007500 _____ C:\Users\BEBOP\Downloads\ResetWUEng.zip
2018-05-13 07:33 - 2018-05-13 07:33 - 000000000 ____D C:\Users\BEBOP\Desktop\Reset Windows Update Tool
2018-05-13 03:37 - 2018-05-13 03:37 - 000000000 ____D C:\Users\BEBOP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2018-05-13 03:35 - 2018-05-13 03:38 - 000000000 ____D C:\Users\BEBOP\AppData\Local\Google
2018-05-13 03:35 - 2018-05-13 03:35 - 000002388 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-05-13 03:35 - 2018-05-13 03:35 - 000002347 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-05-13 03:35 - 2018-05-13 03:35 - 000000000 ____D C:\Program Files (x86)\Google
2018-05-13 03:11 - 2018-05-13 03:11 - 000053006 _____ C:\Users\BEBOP\Desktop\Addition.txt
2018-05-13 03:10 - 2018-05-16 17:55 - 002413056 _____ (Farbar) C:\Users\BEBOP\Desktop\FRST64.exe
2018-05-13 03:10 - 2018-05-16 17:55 - 000025285 _____ C:\Users\BEBOP\Desktop\FRST.txt
2018-05-13 03:10 - 2018-05-16 17:55 - 000000000 ____D C:\Users\BEBOP\Desktop\FRST-OlderVersion
2018-05-13 02:58 - 2018-05-13 02:58 - 000000000 ____D C:\Users\BEBOP\AppData\LocalLow\Temp
2018-05-13 02:45 - 2018-05-13 02:45 - 000000000 ____D C:\Users\BEBOP\AppData\Local\dwskmpc
2018-05-13 02:42 - 2018-05-13 02:42 - 000000000 ____D C:\Users\BEBOP\AppData\Local\svrxedn
2018-05-13 02:39 - 2018-05-13 02:39 - 000000000 ____D C:\Users\BEBOP\AppData\Local\remlagx
2018-05-13 02:36 - 2018-05-13 02:37 - 000000000 ____D C:\AdwCleaner
2018-05-13 01:47 - 2018-05-13 01:47 - 000000000 ____D C:\Users\BEBOP\AppData\Local\cwstzpb
2018-05-12 23:31 - 2018-05-12 23:31 - 000000000 ____D C:\Users\BEBOP\AppData\Local\dtanwhx
2018-05-12 10:17 - 2018-05-12 10:17 - 000000000 ____D C:\Users\BEBOP\AppData\Local\wdebstm
2018-05-12 00:23 - 2018-05-12 00:23 - 000000000 ___HD C:\$Windows.~WS
2018-05-12 00:23 - 2018-05-12 00:23 - 000000000 ____D C:\$WINDOWS.~BT
2018-05-12 00:17 - 2018-05-12 00:30 - 000000000 ____D C:\ESD
2018-05-12 00:16 - 2018-05-12 00:16 - 000000000 ____D C:\Users\BEBOP\AppData\Local\usnarme
2018-05-10 22:40 - 2018-05-10 22:40 - 000000000 ____D C:\Users\BEBOP\AppData\Local\nvckbdw
2018-05-10 06:08 - 2018-05-10 06:08 - 000000000 ____D C:\Users\BEBOP\AppData\Local\dsilbcn
2018-05-10 05:54 - 2018-05-10 06:11 - 000000742 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk
2018-05-10 05:54 - 2018-05-10 05:54 - 000000000 ____D C:\Windows10Upgrade
2018-05-10 05:48 - 2018-05-16 02:06 - 000000000 ____D C:\Users\Administrator\AppData\Local\wmcagent
2018-05-10 05:48 - 2018-05-10 05:48 - 000000000 ____D C:\Users\Administrator\AppData\Local\CEF
2018-05-10 05:48 - 2018-05-10 05:48 - 000000000 ____D C:\Users\Administrator\AppData\Local\avbezis
2018-05-10 05:45 - 2018-05-15 06:13 - 000000000 ____D C:\Users\Administrator\AppData\Local\avoxrdt
2018-05-10 05:45 - 2018-05-10 05:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\svhxciz
2018-05-10 05:44 - 2018-05-10 05:44 - 000000000 ____D C:\Users\Administrator\AppData\Local\Comms
2018-05-10 05:37 - 2018-05-14 14:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\ClassicShell
2018-05-10 05:37 - 2018-05-10 05:37 - 000003368 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3428963390-2178166571-3703012988-500
2018-05-10 05:37 - 2018-05-10 05:37 - 000002398 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-05-10 05:37 - 2018-05-10 05:37 - 000000000 ___RD C:\Users\Administrator\OneDrive
2018-05-10 05:37 - 2018-05-10 05:37 - 000000000 ____D C:\Users\Administrator\Documents\Alienware TactX
2018-05-10 05:37 - 2018-05-10 05:37 - 000000000 ____D C:\Users\Administrator\Documents\AlienFX
2018-05-10 05:37 - 2018-05-10 05:37 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\ClassicShell
2018-05-10 05:36 - 2018-05-15 02:37 - 000000000 ____D C:\Users\Administrator
2018-05-10 05:36 - 2018-05-14 06:38 - 000002343 _____ C:\Users\Administrator\Desktop\Google Chrome.lnk
2018-05-10 05:36 - 2018-05-10 05:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\Packages
2018-05-10 05:36 - 2018-05-10 05:38 - 000000000 ____D C:\Users\Administrator\AppData\Local\NVIDIA Corporation
2018-05-10 05:36 - 2018-05-10 05:36 - 000000000 ___RD C:\Users\Administrator\3D Objects
2018-05-10 05:36 - 2018-05-10 05:36 - 000000000 ___HD C:\Users\Administrator\MicrosoftEdgeBackups
2018-05-10 05:36 - 2018-05-10 05:36 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2018-05-10 05:36 - 2018-05-10 05:36 - 000000000 ____D C:\Users\Administrator\AppData\Local\Publishers
2018-05-10 05:36 - 2018-05-10 05:36 - 000000000 ____D C:\Users\Administrator\AppData\Local\NVIDIA
2018-05-10 05:36 - 2018-05-10 05:36 - 000000000 ____D C:\Users\Administrator\AppData\Local\MicrosoftEdge
2018-05-10 05:36 - 2018-05-10 05:36 - 000000000 ____D C:\Users\Administrator\AppData\Local\Google
2018-05-10 05:36 - 2018-05-10 05:36 - 000000000 ____D C:\Users\Administrator\AppData\Local\ConnectedDevicesPlatform
2018-05-10 05:36 - 2018-05-10 05:36 - 000000000 ____D C:\Users\Administrator\ansel
2018-05-10 05:24 - 2018-05-10 05:24 - 000000000 ____D C:\Users\BEBOP\AppData\Local\dwaezhv
2018-05-10 05:16 - 2018-05-10 05:16 - 000253664 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-05-10 04:44 - 2018-05-15 19:00 - 000028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2018-05-10 04:43 - 2018-05-15 18:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-05-10 04:43 - 2018-05-15 18:51 - 000000000 ____D C:\Program Files\RogueKiller
2018-05-10 04:43 - 2018-05-10 05:16 - 000000000 ____D C:\ProgramData\RogueKiller
2018-05-10 04:42 - 2018-05-10 04:42 - 000000000 ____D C:\Users\BEBOP\AppData\Local\rtsehwb
2018-05-10 04:39 - 2018-05-10 04:39 - 000000000 ____D C:\Users\BEBOP\AppData\Local\cwilpsd
2018-05-10 04:25 - 2018-05-10 04:25 - 000000000 ____D C:\Users\BEBOP\AppData\Local\dsolcbr
2018-05-10 04:22 - 2018-05-10 04:22 - 000000000 ____D C:\Users\BEBOP\AppData\Local\spstwbn
2018-05-10 04:17 - 2018-05-16 17:55 - 000000000 ____D C:\FRST
2018-05-10 04:17 - 2018-05-10 04:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-05-10 04:13 - 2018-05-10 04:13 - 000000000 ____D C:\Users\BEBOP\AppData\Local\sndizuo
2018-05-10 04:12 - 2018-05-10 04:12 - 000250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\15003B69.sys
2018-05-10 04:08 - 2018-05-10 04:08 - 000000000 ____D C:\Users\BEBOP\AppData\Local\csdzvpo
2018-05-10 04:07 - 2018-05-10 04:07 - 000250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\2D0337C3.sys
2018-05-10 03:37 - 2018-05-10 03:37 - 000000000 ____D C:\Users\BEBOP\AppData\Local\sckngdv
2018-05-10 03:31 - 2018-05-10 03:31 - 000250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\3B391C50.sys
2018-05-10 03:30 - 2018-05-10 03:30 - 000000000 ____D C:\Program Files\Malwarebytes
2018-05-10 03:29 - 2018-05-10 04:17 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-05-10 03:23 - 2018-05-10 03:23 - 000000000 ____D C:\Users\BEBOP\AppData\Local\sihkwgm
2018-05-10 03:13 - 2018-05-07 15:26 - 000132488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2018-05-10 03:12 - 2018-05-15 22:29 - 000152184 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2018-05-10 03:09 - 2018-05-08 17:22 - 001990688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6439764.dll
2018-05-10 03:09 - 2018-05-08 17:22 - 001561504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2018-05-10 03:09 - 2018-05-08 17:22 - 001467992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6439764.dll
2018-05-10 03:09 - 2018-05-08 17:22 - 001417816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2018-05-10 03:09 - 2018-05-08 17:22 - 001215576 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2018-05-10 03:09 - 2018-05-08 17:22 - 001091432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2018-05-10 03:09 - 2018-05-08 17:22 - 000749928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2018-05-10 03:09 - 2018-05-08 17:22 - 000626776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2018-05-10 03:09 - 2018-05-08 17:22 - 000608704 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2018-05-10 03:09 - 2018-05-08 17:22 - 000517888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 040346984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 035250776 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 031273728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 025987296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 013725744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 011271400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 004347832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 003758496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 001349712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 001157392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 001064424 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 000904720 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 000813912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2018-05-10 03:09 - 2018-05-08 17:21 - 000652344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2018-05-10 03:09 - 2018-05-08 17:20 - 017779440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2018-05-10 03:09 - 2018-05-08 17:20 - 015191088 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2018-05-10 03:00 - 2018-05-10 03:00 - 000000000 ____D C:\Users\BEBOP\AppData\Local\upkdhgc
2018-05-09 03:01 - 2018-05-09 03:01 - 000000000 ____D C:\Users\BEBOP\AppData\Local\wdcusbv
2018-05-09 01:55 - 2018-05-13 02:52 - 000004210 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-05-09 01:19 - 2018-05-09 01:19 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\512492E1.sys
2018-05-09 01:18 - 2018-05-09 01:18 - 000000000 ____D C:\Users\BEBOP\AppData\Local\exsbcwo
2018-05-09 01:13 - 2018-05-09 01:13 - 000000000 ____D C:\Users\BEBOP\AppData\Local\sikhcpw
2018-05-09 01:06 - 2018-05-13 01:45 - 000000000 ____D C:\WINDOWS\system32\Catroot2.bak
2018-05-09 00:58 - 2018-05-09 02:24 - 000000000 ____D C:\WINDOWS\SoftwareDistribution.bak
2018-05-09 00:22 - 2018-05-09 00:22 - 000000000 ____D C:\Users\BEBOP\AppData\Local\ranbuet
2018-05-09 00:18 - 2018-05-09 00:18 - 000030888 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
2018-05-09 00:18 - 2018-05-09 00:18 - 000029352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll
2018-05-09 00:17 - 2018-05-09 00:17 - 000019088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr100_clr0400.dll
2018-05-09 00:17 - 2018-05-09 00:17 - 000019088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr100_clr0400.dll
2018-05-09 00:15 - 2018-05-13 02:49 - 000000000 ____D C:\Users\BEBOP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2018-05-09 00:15 - 2018-05-09 00:15 - 000000000 ____D C:\Program Files (x86)\Alienware Update
2018-05-09 00:05 - 2018-05-09 00:05 - 000000000 ____D C:\Users\BEBOP\AppData\Local\avngext
2018-05-08 16:55 - 2018-05-08 16:55 - 000000000 ____D C:\Users\BEBOP\AppData\Local\dtcbplz
2018-05-08 01:06 - 2018-04-27 22:04 - 001990584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6439731.dll
2018-05-08 01:06 - 2018-04-27 22:04 - 001467992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6439731.dll
2018-05-08 01:06 - 2018-04-24 15:33 - 000046064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2018-05-02 11:55 - 2018-05-02 11:55 - 000000000 ____D C:\Users\BEBOP\AppData\Local\wmmsdzo
2018-05-01 12:13 - 2018-05-01 12:13 - 000000000 ____D C:\Users\BEBOP\AppData\Local\nvhagxt
2018-04-30 18:56 - 2018-04-30 18:56 - 000000000 ____D C:\Users\BEBOP\AppData\Local\wenkxut
2018-04-29 17:55 - 2018-04-29 17:55 - 000000000 ____D C:\Users\BEBOP\AppData\Local\weramlp
2018-04-29 10:26 - 2018-04-29 10:26 - 000000000 ____D C:\Users\BEBOP\AppData\Local\pchaodk
2018-04-29 02:30 - 2018-05-13 03:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NordVPN
2018-04-29 02:30 - 2018-05-13 03:23 - 000000000 ____D C:\Program Files (x86)\NordVPN
2018-04-28 19:32 - 2018-04-28 19:32 - 000000000 ____D C:\Users\BEBOP\AppData\Local\svolmur
2018-04-28 06:46 - 2018-04-28 06:46 - 000000000 ____D C:\Users\BEBOP\AppData\Local\pseozkc
2018-04-28 02:26 - 2018-04-28 02:26 - 000000000 ____D C:\Users\BEBOP\AppData\Local\scmuwgh
2018-04-28 01:54 - 2018-04-28 01:54 - 000000000 ____D C:\Users\BEBOP\AppData\Local\snswdkx
2018-04-28 01:50 - 2018-05-13 03:21 - 000000000 ____D C:\Users\BEBOP\AppData\Local\SaferVPN
2018-04-28 01:50 - 2016-04-21 05:10 - 000027136 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\tap0901.sys
2018-04-28 00:56 - 2018-04-28 00:56 - 000000000 ____D C:\Users\BEBOP\AppData\Local\iaknmcb
2018-04-28 00:49 - 2018-04-28 00:49 - 000000000 ____D C:\Users\BEBOP\AppData\Local\nicbzdt
2018-04-28 00:36 - 2018-04-28 00:36 - 000000000 ____D C:\ProgramData\NordVpn
2018-04-28 00:36 - 2018-04-28 00:36 - 000000000 ____D C:\ProgramData\Caphyon
2018-04-28 00:35 - 2018-04-28 00:36 - 000000000 ____D C:\Users\BEBOP\AppData\Local\NordVPN
2018-04-28 00:34 - 2018-05-02 11:59 - 000000000 ____D C:\Users\BEBOP\AppData\Roaming\NordVPN
2018-04-28 00:34 - 2018-04-28 00:34 - 000000000 ____D C:\Program Files\TAP-NordVPN
2018-04-27 03:33 - 2018-04-27 03:33 - 000000000 ____D C:\Users\BEBOP\AppData\Local\sbimknz
2018-04-26 21:32 - 2018-04-26 21:32 - 000000000 ____D C:\Users\BEBOP\AppData\Local\wecodbi
2018-04-25 22:27 - 2018-04-25 22:27 - 000000000 ____D C:\Users\BEBOP\AppData\Local\psbkgal
2018-04-25 20:27 - 2018-04-25 20:27 - 000000000 ____D C:\Users\BEBOP\AppData\Local\sceknbg
2018-04-25 07:25 - 2018-04-25 07:25 - 000000000 ____D C:\Users\BEBOP\AppData\Local\sprkxdc
2018-04-24 19:01 - 2018-04-24 19:01 - 000000000 ____D C:\Users\BEBOP\AppData\Local\svnlzoi
2018-04-23 20:59 - 2018-04-23 20:59 - 000000000 ____D C:\Users\BEBOP\AppData\Local\csakdrt
2018-04-22 21:57 - 2018-04-22 21:57 - 000000000 ____D C:\Users\BEBOP\AppData\Local\pwexvrg
2018-04-22 21:54 - 2018-04-22 21:54 - 000000000 ____D C:\Users\BEBOP\AppData\Local\cwaving
2018-04-22 21:39 - 2018-04-22 21:39 - 000000000 ____D C:\Users\BEBOP\AppData\Local\niakzpl
2018-04-22 01:06 - 2018-04-22 01:06 - 000000000 ____D C:\Users\BEBOP\AppData\Local\csdokxr
2018-04-21 13:19 - 2018-04-21 13:19 - 000000000 ____D C:\Users\BEBOP\AppData\Local\zaebltv
2018-04-20 20:17 - 2018-04-20 20:17 - 000000000 ____D C:\Users\BEBOP\AppData\Local\siaxcrd
2018-04-20 16:01 - 2018-04-20 16:01 - 000000000 ____D C:\Users\BEBOP\AppData\Local\cwhnutb
2018-04-19 23:04 - 2018-05-13 03:35 - 000003416 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-04-19 23:04 - 2018-05-13 03:35 - 000003292 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-04-19 23:03 - 2018-05-09 00:16 - 000000000 ____D C:\Users\BEBOP\AppData\Local\Deployment
2018-04-19 22:58 - 2018-04-19 22:58 - 000000000 ____D C:\Users\BEBOP\AppData\Local\msnkuat
2018-04-19 22:57 - 2018-05-16 17:44 - 000004148 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{8864AFCE-56FE-4153-9B0C-07D6B653AB2C}
2018-04-19 22:48 - 2018-04-19 22:48 - 000000000 ____D C:\Users\BEBOP\AppData\Local\rahdleg
2018-04-19 22:33 - 2018-04-19 22:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard
2018-04-19 22:33 - 2018-04-19 22:33 - 000000000 ____D C:\Program Files\EaseUS
2018-04-19 22:24 - 2018-04-19 22:24 - 000000000 ____D C:\Users\BEBOP\AppData\Local\spmoewc
2018-04-19 22:19 - 2018-04-19 22:19 - 000072816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\yvgzwbiu.sys
2018-04-19 22:08 - 2018-04-21 06:28 - 000000000 ____D C:\Users\BEBOP\AppData\Local\csiobtv
2018-04-19 22:05 - 2018-05-15 02:49 - 000000000 ____D C:\Users\BEBOP\AppData\Local\exibsud
2018-04-19 22:05 - 2018-04-19 22:05 - 000000000 ____D C:\Users\BEBOP\AppData\Local\cosxhun
2018-04-19 22:04 - 2018-05-15 22:23 - 002888704 _____ C:\WINDOWS\system32\snelowksvc.exe
2018-04-19 22:04 - 2018-05-09 01:09 - 000000000 ____D C:\Program Files (x86)\muting
2018-04-19 22:04 - 2018-04-19 22:04 - 000000012 _____ C:\WINDOWS\b20769684
2018-04-19 22:04 - 2018-04-19 22:04 - 000000000 ____D C:\WINDOWS\SysWOW64\dsmxcol
2018-04-19 22:04 - 2018-04-19 22:04 - 000000000 ____D C:\WINDOWS\system32\dsmxcol
2018-04-19 22:03 - 2018-04-19 22:03 - 000000000 ____D C:\Users\BEBOP\AppData\Roaming\et
2018-04-19 05:27 - 2018-04-19 05:27 - 002211328 _____ C:\WINDOWS\060f4e2c34031fa5f5020a7fab20e0cb.exe
2018-04-19 05:27 - 2018-04-19 05:27 - 000039553 _____ C:\WINDOWS\uninstaller.dat